Vulnerability Search Top
Show Search Menu
Vendor Name
プロダクト・サービス名
Title
Urgent
Important
Warning
Warning
CVE
CWE
公開-検索開始年
公開-検索開始月
公開-検索開始日
公開-検索終了年
公開-検索終了月
公開-検索終了日
脅威度ソート
In descending order of publication date
In descending order of update date
Number of items displayed

You can search for vulnerabilities managed by JVN (Japan Vulnerability Note) and NVD (National Vulnerability Database).
Search keywords must be entered in English otherwise will not be searched in both JVN and NVD.

To search by CWE, please refer to the CWE Overview and check the CWE number.

  • Urgent
  • Important
  • Warning
  • Low
JVN Vulnerability Information

Update Date":Jan. 31, 2025, 4:03 p.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Impact
Show
Exploit
PoC
Search
551 9.8 緊急
Network
Sapplica Sentrifugo Sapplica の Sentrifugo における SQL インジェクションの脆弱性 CWE-89
SQLインジェクション
CVE-2024-29874 2025-01-27 13:34 2024-03-21 Show GitHub Exploit DB Packet Storm
552 6.1 警告
Network
Sapplica Sentrifugo Sapplica の Sentrifugo におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-29879 2025-01-27 13:34 2024-03-21 Show GitHub Exploit DB Packet Storm
553 9.1 緊急
Network
Palo Alto Networks PAN-OS Palo Alto Networks の PAN-OS における脆弱性 CWE-282
CWE-Other
CVE-2024-3383 2025-01-27 13:34 2024-04-10 Show GitHub Exploit DB Packet Storm
554 5.4 警告
Network
exclusiveaddons exclusive addons for elementor exclusiveaddons の WordPress 用 exclusive addons for elementor におけるクロスサイトスクリプティングの脆弱性 CWE-79
クロスサイト・スクリプティング(XSS)
CVE-2024-4618 2025-01-27 13:34 2024-05-15 Show GitHub Exploit DB Packet Storm
555 7.2 重要
Network
aipower aipower WordPress 用 aipower における信頼できないデータのデシリアライゼーションに関する脆弱性 CWE-502
信頼性のないデータのデシリアライゼーション
CVE-2025-0428 2025-01-27 13:34 2025-01-22 Show GitHub Exploit DB Packet Storm
556 5.3 警告
Network
Palo Alto Networks PAN-OS Palo Alto Networks の PAN-OS における解釈の競合に関する脆弱性 CWE-436
CWE-436
CVE-2024-3386 2025-01-27 13:34 2024-04-10 Show GitHub Exploit DB Packet Storm
557 6.8 警告
Physics
Palo Alto Networks PAN-OS Palo Alto Networks の PAN-OS における脆弱性 CWE-20
CWE-noinfo
CVE-2024-5913 2025-01-27 13:34 2024-07-10 Show GitHub Exploit DB Packet Storm
558 7.5 重要
Network
Magma Magma Magma における境界外書き込みに関する脆弱性 CWE-120
CWE-787
CVE-2024-24423 2025-01-27 13:32 2024-01-25 Show GitHub Exploit DB Packet Storm
559 5.3 警告
Network
Timothee Boussus Your Spotify Timothee Boussus の Your Spotify におけるインジェクションに関する脆弱性 CWE-74
CWE-74
CWE-943
CVE-2024-28192 2025-01-27 13:22 2024-03-13 Show GitHub Exploit DB Packet Storm
560 7.5 重要
Network
Magma Magma Magma における到達可能なアサーションに関する脆弱性 CWE-617
CWE-617
CVE-2023-37029 2025-01-27 12:33 2023-06-28 Show GitHub Exploit DB Packet Storm
NVD Vulnerability Information

Update Date:Jan. 31, 2025, 4:11 a.m.

No CVSS Level
Attach Vector
Vendor Name Project Name Title CWE CVE Update Date Publication Date Show Affected Exploit
PoC
Search
681 - - - Missing Authorization vulnerability in Kadence WP Gutenberg Blocks by Kadence Blocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Gutenberg Blocks by Ka… CWE-862
 Missing Authorization
CVE-2025-24753 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
682 - - - Missing Authorization vulnerability in GoDaddy CoBlocks allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects CoBlocks: from n/a through 3.1.13. CWE-862
 Missing Authorization
CVE-2025-24751 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
683 - - - Missing Authorization vulnerability in ExactMetrics ExactMetrics allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ExactMetrics: from n/a through 8.1.0. CWE-862
 Missing Authorization
CVE-2025-24750 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
684 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Popup Maker Popup Maker allows Stored XSS. This issue affects Popup Maker: from n/a through 1.20.… CWE-79
Cross-site Scripting
CVE-2025-24746 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
685 - - - Cross-Site Request Forgery (CSRF) vulnerability in FluentSMTP & WPManageNinja Team FluentSMTP allows Cross Site Request Forgery. This issue affects FluentSMTP: from n/a through 2.2.80. CWE-352
 Origin Validation Error
CVE-2025-24739 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
686 - - - Cross-Site Request Forgery (CSRF) vulnerability in NowButtons.com Call Now Button allows Cross Site Request Forgery. This issue affects Call Now Button: from n/a through 1.4.13. CWE-352
 Origin Validation Error
CVE-2025-24738 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
687 - - - Missing Authorization vulnerability in Metaphor Creations Post Duplicator allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Post Duplicator: from n/a through… CWE-862
 Missing Authorization
CVE-2025-24736 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
688 - - - Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AddonMaster Post Grid Master allows PHP Local File Inclusion. This issue affec… CWE-98
 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE-2025-24733 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
689 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Booking & Appointment - Repute Infosystems BookingPress allows DOM-Based XSS. This issue affects … CWE-79
Cross-site Scripting
CVE-2025-24732 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm
690 - - - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IP2Location Download IP2Location Country Blocker allows Stored XSS. This issue affects Download I… CWE-79
Cross-site Scripting
CVE-2025-24731 2025-01-25 03:15 2025-01-25 Show GitHub Exploit DB Packet Storm